Fallos del tipo CWE-22

5970 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-33033HIGHQsync CentralEPSS 0.5%CVE-2025-30271MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-33038HIGHQsync CentralEPSS 0.5%CVE-2025-3214MEDIUMJFinal CMS readTemplate engine.getTemplate path traversalEPSS 0.5%CVE-2024-5433MEDIUMPath Traversal in Campbell Scientific CSI Web Server and RTMCEPSS 0.5%CVE-2022-3976MEDIUMMZ Automation libiec61850 MMS File Services mms_client_files.c path traversalEPSS 0.5%CVE-2024-38746HIGHWordPress MakeStories (for Google Web Stories) plugin <= 3.0.3 - Arbitrary File Download and SSRF vulnerabilityEPSS 0.5%CVE-2025-6589LOWWith MultiBlocks enabled and a user who is suppressed via a MultiBlock, a user without 'hideuser' can see the hidden username in the BlockListEPSS 0.5%CVE-2026-81837MEDIUMRooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversalEPSS 0.5%CVE-2026-76842HIGHMercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment ClientsEPSS 0.5%CVE-2024-37372LOWThe Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignored, which is not alwEPSS 0.5%CVE-2026-39844MEDIUMNiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath SanitizationEPSS 0.5%CVE-2025-66251HIGHUnauthenticated Path Traversal with Arbitrary File DeletionEPSS 0.5%CVE-2026-40384MEDIUMJoomla! Core - [20260510] - Path traversal in com_media webservice endpointEPSS 0.5%CVE-2026-45569HIGHRoxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)EPSS 0.5%CVE-2026-42598MEDIUMPode: Directory Traversal is possible on Static RoutesEPSS 0.5%CVE-2026-19302MEDIUMLangflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor componentsEPSS 0.5%CVE-2023-39407—The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.EPSS 0.5%CVE-2026-65878HIGHJoomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1EPSS 0.5%CVE-2026-16088MEDIUMhalo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversalEPSS 0.5%